Free passive scan

Free DNS Security Check

Free tool

Check CAA record presence and wildcard DNS exposure in 60 seconds, with guidance on DNSSEC and the rest of your DNS setup.

  • CAA presence
  • Wildcard detection
  • DNS fix guidance
No credit card requiredRead-only, no exploitationNo setup or code required
Used by 5,000+ developers and engineering teams
Oracle logoShopify logoGoDaddy logoChubb logoToshiba logoMAPFRE logoBelfius logoHolcim logo

What you get for free

18 core security checks via this tool, passive scans, step-by-step remediation, security score on every result.

What Essential adds from €199/mo

Pentest credits every month, +17 advanced checks, weekly passive scans, email alerts and audit-ready PDFs for SOC 2 / ISO 27001 / PCI.

Why DNS Security Matters

Attack Prevention:
  • Prevents DNS hijacking and cache poisoning attacks
  • Protects against subdomain takeover vulnerabilities
  • Reduces risk of certificate mis-issuance
  • Mitigates DNS-based DDoS amplification attacks
Data Integrity:
  • Ensures DNS responses haven't been tampered with
  • Validates authenticity of DNS records
  • Provides cryptographic proof of DNS data integrity
  • Protects against man-in-the-middle DNS attacks
Compliance & Trust:
  • Meets security compliance requirements
  • Enhances user trust and confidence
  • Demonstrates security best practices
  • Reduces liability from security incidents

What this checker validates

Certificate Authority Authorization (CAA):
  • CAA record presence detection
DNS Security Risks:
  • Wildcard DNS record detection

This check doesn't validate DNSSEC signatures or look for subdomain takeovers. Use the subdomain takeover checker for dangling CNAMEs, and your DNS provider or a DNSSEC debugger to confirm your chain of trust.

How to improve DNS security

DNSSEC Implementation:
  • Enable DNSSEC at your domain registrar or DNS provider
  • Generate and configure DNSKEY records
  • Publish DS records with your registrar
  • Monitor DNSSEC chain of trust regularly
CAA Record Configuration:
  • Add CAA records to control certificate issuance
  • Specify authorized Certificate Authorities
  • Configure wildcard certificate policies
  • Set up violation reporting (iodef)
DNS Security Hardening:
  • Remove unnecessary wildcard DNS records
  • Implement proper TTL values to prevent DNS rebinding
  • Secure subdomains to prevent takeover attacks
  • Monitor DNS changes and anomalies

Tool-specific questions

What is DNSSEC and why is it important?

DNSSEC (DNS Security Extensions) adds cryptographic signatures to DNS records, ensuring data integrity and authenticity. It helps prevent DNS hijacking and cache poisoning. This checker doesn't validate DNSSEC, so confirm your chain of trust with your DNS provider or a DNSSEC debugger.

How do I enable DNSSEC for my domain?

Enable DNSSEC at your domain registrar or DNS provider, generate DNSKEY records, and publish DS (Delegation Signer) records with your registrar. The process varies by provider, but most offer automated DNSSEC setup. Expect some propagation time for full deployment.

What are CAA records and how do they improve security?

CAA (Certificate Authority Authorization) records specify which Certificate Authorities can issue SSL/TLS certificates for your domain. Our checker detects the presence of CAA records, which is the first step in preventing unauthorized certificate issuance and reducing the risk of certificate-based attacks.

What's the difference between DNS and DNSSEC?

DNS is the system that translates domain names to IP addresses. DNSSEC adds cryptographic signatures to DNS records, ensuring the data hasn't been tampered with. While DNS provides the service, DNSSEC provides the security layer to protect against attacks.

Can DNSSEC impact website performance?

DNSSEC can slightly increase DNS response sizes due to cryptographic signatures, but the performance impact is minimal for most websites. The security benefits far outweigh the small performance cost, and modern DNS infrastructure handles DNSSEC efficiently.

What are wildcard DNS records and why are they risky?

Wildcard DNS records (*.domain.com) resolve any subdomain to the same IP address. While convenient, they can expose unintended services, enable subdomain takeover attacks, and make it harder to track legitimate subdomains. Use specific records when possible.

How often should I review my DNS security configuration?

Review DNS security settings quarterly or after any infrastructure changes. Monitor for unauthorized DNS changes, check your DNSSEC chain of trust, and confirm your CAA records are still in place. Use Barrion's continuous monitoring to track DNS security posture over time.

What's DNS cache poisoning and how does DNSSEC prevent it?

DNS cache poisoning occurs when attackers inject false DNS records into DNS caches. DNSSEC prevents this by cryptographically signing DNS records, making it impossible to forge responses without the private key. This ensures users receive authentic DNS data.

What is subdomain takeover and how do I check for it?

Subdomain takeover occurs when a subdomain points to a service that no longer exists, allowing attackers to claim it. This DNS check doesn't cover it. Use Barrion's subdomain takeover checker, which looks for CNAMEs that point to unclaimed cloud resources.
Why Barrion

Built for the engineers who already have enough to fix.

Speed

Fast results

Instant analysis with a detailed report. You see findings as the scan runs, not after.
Coverage

Comprehensive checks

The full passive scan runs 18 checks on the free plan, covering TLS, headers and cookies. Paid plans run 35+ and add CORS, DNS, email auth and more.
Action

Step-by-step fixes

Every finding ships with the exact remediation step for your framework. Hand it to the engineer who owns the surface.
FAQ

Frequently asked.

What is Barrion?
Barrion runs continuous, agentic AI penetration tests of web applications and APIs. AI agents test your app the way an attacker would, safely, on a schedule or on demand. Findings are checked against the live app before they're reported, and tracked across runs as new, still open, resolved or regressed. From Standard level up, a security engineer reviews each report. Barrion AB is based in Gothenburg, Sweden. A free passive scan is the quickest way to start.
How safe is Barrion to use for security testing?
AI pentests send real test requests, so they're rate-limited and non-destructive, and you approve the exact scope before a single request goes out. You can point them at staging too. The free passive scan only reads your live app. It never submits forms, brute-forces endpoints or touches anything that changes state, so it's safe to run against production.
What types of security issues does Barrion identify?
AI pentests look for the issues an attacker could exploit, like SQL injection, cross-site scripting and broken access control. Findings are checked against your live app, and confirmed ones come with the request and response that prove them. Anything we couldn't confirm is clearly marked and capped in severity. The passive scan catches misconfigurations in TLS and HTTPS, security headers, cookie flags, CORS policy, DNS records, email authentication (SPF, DKIM, DMARC) and network exposure.
What specific security checks does Barrion perform?
Barrion covers two surfaces. AI pentesting is the active part: specialist agents chain requests to find exploitable flaws such as SQL injection, cross-site scripting and broken access control. Findings are checked against your live app, and confirmed ones come with the request and response that prove them. The passive scan is read-only and safe to point at production. On paid plans it runs 35+ checks (18 on the free plan): transport security (HTTPS, HSTS, TLS version, cipher suites, certificate expiry, hostname and chain validity, OCSP stapling), HTTP response headers (Referrer-Policy, Permissions-Policy, X-Content-Type-Options, Content-Type, server information disclosure), CSP and framing (Content-Security-Policy, bypass detection, Trusted Types, X-Frame-Options), cross-origin policy (COOP, COEP, CORP and the full CORS header set), cookie flags and anti-CSRF tokens, mixed content, vulnerable JavaScript libraries, DNS records including DNSSEC and CAA, email authentication (SPF, DKIM, DMARC), open ports and subdomain takeover. Findings from both are ranked by severity and come with step-by-step remediation.
Will my auditor or enterprise customers accept the pentest report?
The report maps every finding to OWASP WSTG, a security engineer reviews it from Standard up and signs it off from Deep up, and a free retest shows what you fixed. Teams use it as evidence for SOC 2, ISO 27001 and NIS2 work. Whether it's accepted is up to your auditor.
How often does Barrion test my app?
Continuously or on demand. On the Business plan you save a pentest and it reruns daily, weekly, monthly, quarterly, every six months, yearly or on your own rhythm. On any plan you can start a pentest or a passive scan on demand. A passive scan also runs on a schedule and alerts you when something new shows up.
Is Barrion suitable for security testing of all business sizes?
Yes. Solo developers often start with the free passive scan and a single pentest. Teams with several apps run pentests on a schedule, and it fits alongside the tools you already run.
How does Barrion handle data security and privacy during security testing?
Passive scans are read-only: they only look at what your app already exposes publicly. For AI pentests we keep the findings in your report, and confirmed findings include the request and response behind them, so you can review and reproduce them. Test credentials you add are encrypted. Barrion is hosted in Sweden, data is stored in the EU and AI processing runs in the EU. Our trust page lists every subprocessor. Pentests are rate-limited and only run inside the scope you approve.
What if I'm not satisfied with Barrion's security testing service?
You can cancel anytime in the dashboard, and paid plans carry a 14-day refund window from the first charge. If something isn't right, contact us and we'll make it work for your team.
How does Barrion help with SOC 2, ISO 27001, NIS2, and other compliance frameworks?
Barrion's pentest reports come as PDF, XLSX and JSON, mapped to all 97 OWASP WSTG test cases, with engineer review from Standard up, sign-off from Deep up and a free retest after fixes. Teams use them as evidence that supports SOC 2, ISO 27001, PCI DSS and NIS2 work. Whether a report is accepted is up to your auditor or customer.

Anything else? Email contact@barrion.io.

A scan shows the surface. A pentest tests what gets in.

Passive scan

  • Reads what your app already exposes
  • Never logs in or submits a form
  • Cannot confirm what is exploitable

Active AI pentest

  • Tests your app the way an attacker would
  • Chains requests to confirm real exploits
  • Replays findings against your live app
  • Runs on a schedule or on demand, retests free

Probes for

  • SQL injection
  • Broken access control
  • IDOR
  • SSRF
  • Business-logic abuse

How AI pentesting works

Paid in credits. Free retests of found issues, and expert review from Standard up.